nagios packages signed with sha-1
Posted: Wed Jul 26, 2023 9:01 am
Hi,
on our rhel 8.8 nagiosxi server we have messages that the following pakckages are signed with a poor secure old algorithm sha-1.
Package reposiroty
snmptt nagiosxi-deps
perl-Params-Validate codeready-builder-for-rhel-8-x86_64-rpms
perl-DateTime codeready-builder-for-rhel-8-x86_64-rpms
python3-rrdtool codeready-builder-for-rhel-8-x86_64-rpms
perl-Class-Accessor codeready-builder-for-rhel-8-x86_64-rpms
shellinabox nagiosxi-deps
php-imap nagiosxi-deps
perl-Module-Implementation codeready-builder-for-rhel-8-x86_64-rpms
perl-Digest-SHA1 codeready-builder-for-rhel-8-x86_64-rpms
php-pecl-ssh2 nagiosxi-deps
perl-IO-stringy codeready-builder-for-rhel-8-x86_64-rpms
perl-Class-Singleton codeready-builder-for-rhel-8-x86_64-rpms
Reinstalling the packages seems to solve only the sha-1 signing issue for packages manteined in the codeready-builder-for-rhel-8-x86_64-rpms reposiroty en not the ones available from de nagiosxi-deps repositoyy.
Can you build those packages with supported signatures so we can re-install the new packages?
Regards,
Christian
on our rhel 8.8 nagiosxi server we have messages that the following pakckages are signed with a poor secure old algorithm sha-1.
Package reposiroty
snmptt nagiosxi-deps
perl-Params-Validate codeready-builder-for-rhel-8-x86_64-rpms
perl-DateTime codeready-builder-for-rhel-8-x86_64-rpms
python3-rrdtool codeready-builder-for-rhel-8-x86_64-rpms
perl-Class-Accessor codeready-builder-for-rhel-8-x86_64-rpms
shellinabox nagiosxi-deps
php-imap nagiosxi-deps
perl-Module-Implementation codeready-builder-for-rhel-8-x86_64-rpms
perl-Digest-SHA1 codeready-builder-for-rhel-8-x86_64-rpms
php-pecl-ssh2 nagiosxi-deps
perl-IO-stringy codeready-builder-for-rhel-8-x86_64-rpms
perl-Class-Singleton codeready-builder-for-rhel-8-x86_64-rpms
Reinstalling the packages seems to solve only the sha-1 signing issue for packages manteined in the codeready-builder-for-rhel-8-x86_64-rpms reposiroty en not the ones available from de nagiosxi-deps repositoyy.
Can you build those packages with supported signatures so we can re-install the new packages?
Regards,
Christian